# refactor(import): drop unused Provenance from imported checkpoints

`1f63eb4`→[main](/content/gh/entireio/cli/commits/main/index.html)·

computermode·3w ago·7 files·+15 added/-108 removed

Provenance was written to metadata.json but never read: idempotency comes from
the deterministic checkpoint ID (sha256(sessionID/turnUUID)), and explain never
cited it. Removing the Provenance struct/field and the now-dead Turn fields
(ParentUUID) and import-version constant. Imported checkpoints keep Kind and the
Imported flag.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

## Sessions

4315ab0b3062View transcript

## Changes

7

- api/checkpoint

- Mmetadata.go-23  
  - Mmetadata_test.go+1/-30

- cmd/entire/cli

- agentimport

- Magentimport.go+4/-38  
    - Mclaude.go+10/-12

- checkpoint

- Maliases.go-1  
    - Mpersistent.go-1  
    - Mpersistent_imported_test.go-3

```  
10 unmodified lines
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
14
15
16
119 unmodified lines

136
137
138
154
155
156
157
139
140
141
209 unmodified lines

351
352
353
373
374
375
376
354
355
356

10 unmodified lines

"github.com/go-git/go-git/v6/plumbing"

// Provenance records where an imported checkpoint came from, so explain/search
// can cite the original transcript honestly and re-import stays idempotent.
// Only set for imported (Kind == "imported") checkpoints.
type Provenance struct {
	Source         string `json:"source"`                // e.g. "claude-code"
	TranscriptFile string `json:"transcript_file"`       // basename of the source transcript (no absolute path: avoid leaking local usernames/repo layout)
	SessionID      string `json:"session_id"`            // agent session id
	TurnUUID       string `json:"turn_uuid"`             // uuid of the user-prompt line that starts this turn
	ParentUUID     string `json:"parent_uuid,omitempty"` // parent uuid of that line
	LineStart      int    `json:"line_start"`            // 0-indexed start line of this turn in the source
	LineEnd        int    `json:"line_end"`              // exclusive end line (next turn start or EOF)
	ContentHash    string `json:"content_hash"`          // hash of the redacted turn slice (never raw content)
	ImportVersion  int    `json:"import_version"`        // importer schema version
}

// WriteOptions contains options for writing a persistent checkpoint.
type WriteOptions struct {
	// CheckpointID is the stable 12-hex-char identifier
	
	// Kind identifies the session purpose (e.g., "agent_review"). Empty for normal sessions.
	Kind string

// Provenance records the source of an imported checkpoint. Only set when
	// Kind == "imported".
	Provenance *Provenance

// ReviewSkills is the snapshot of skills used (only meaningful when Kind is a review kind).
	// May be empty when a review is attached post-hoc without declared skills.
	ReviewSkills []string
}

// contentHash returns "sha256:<hex>" over the redacted turn slice
// (redLines[LineStart:LineEnd]). Hashing redacted content keeps the stored
// provenance hash from enabling confirmation attacks against guessed raw
// prompt/output text. Returns "" when the bounds are empty.
func contentHash(redLines [][]byte, turn Turn) string {
	start, end := turn.LineStart, turn.LineEnd
	if start < 0 {
		start = 0
	}
	if end > len(redLines) {
		end = len(redLines)
	}
	if start >= end {
		return ""
	}
	sum := sha256.Sum256(joinLines(redLines[start:end]))
	return "sha256:" + hex.EncodeToString(sum[:])
}

func writeTurn(ctx context.Context, stores *cp.Stores, imp Importer, cid id.CheckpointID, sf SessionFile, red redact.RedactedBytes, hash string, turn Turn) error {
	prov := &cp.Provenance{
		Source: imp.Name(), TranscriptFile: filepath.Base(sf.Path), SessionID: sf.SessionID,
		TurnUUID: turn.UUID, ParentUUID: turn.ParentUUID,
		LineStart: turn.LineStart, LineEnd: turn.LineEnd,
		ContentHash: hash, ImportVersion: importVersion,
	}
}
```
